Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
1826"Zero-Days" Without Incident - Compromising Angular via Expired npm Publisher Email Domains Supply chain attack GitHub Matthew Bryant (@IAmMandatory) Bug Bounty2022-02-112023-06-13
1825A tale of 0-Click Account Takeover and 2FA Bypass. Account takeover Password reset MFA bypass NA Firas Fatnassi (@Fatnass1F1ras) Bug Bounty2022-02-122023-06-13
1824Broken Link Hijacking - Mr. User-Agent Broken link hijacking NA Jerry Shah (@Jerry) Bug Bounty2022-02-132023-06-13
1823How i made 15k$ from Remote Code Execution Vulnerability Code injection RCE Self-XSS NA Abdulrahman Makki (@AMakki1337) Bug Bounty2022-02-132023-06-13
1822Hacking AWS Cognito Misconfiguration to Zero Click Account Takeover AWS misconfiguration Account takeover NA Preetham Bomma (@cyber01_) Bug Bounty2022-02-142023-06-13
1821My First Bounty and How I Got It Subdomain takeover NA Aneesha D (@interc3pt3r) Bug Bounty2022-02-142023-06-13
1820BigQuery SQL Injection Cheat Sheet SQL injection NA Ozgur Alp (@ozgur_bbh) Bug Bounty2022-02-142023-06-13
1814Hacked Dutch Government Website. All I got was this l̶o̶u̶s̶y̶ cool T-Shirt. Information disclosure Dutch Government Romesh chander Bug Bounty2022-02-162023-06-13
1813My First Reflected XSS Bug Bounty — Google Dork — $xxx Reflected XSS NA Proviesec (@proviesec) Bug Bounty2022-02-162023-06-13
1811How I earned $9000 with Privilege escalations Privilege escalation NA Junaid Khan (@JunoonBro) Bug Bounty2022-02-162023-06-13
1810CVE-2022-0478 - WooCommerce Event-Manager Plugin SQL Injection SQL injection Security code review Automattic (WooCommerce) Castilho (@castilho101) Bug Bounty2022-02-162023-06-13
1808403 forbidden bypass & Accessing config files using a header 403 bypass Authorization flaw NA vishnurajr Bug Bounty2022-02-172023-06-13
1807Recon and YouTube, is that a thing? Subdomain takeover NA Marcos IAF / Rohit (@marcos_iaf) Bug Bounty2022-02-172023-06-13
1802Passive Recon with Spyse (Part-II) Subdomain takeover AWS misconfiguration NA remonsec (@remonsec) Bug Bounty2022-02-192023-06-13
1801My Experience of Hacking Dutch Government - Dutch Government remonsec (@remonsec) Bug Bounty2022-02-192023-06-13
1800CVE-2022-23835: A security analysis of Visual Voicemail Voicemail hacking AT&T T-Mobile Chris Talbot Bug Bounty2022-02-192023-06-13
1799Bypassing Cloudflare’s WAF! XSS WAF bypass NA Friendly (@SkeletorKeys) Bug Bounty2022-02-192023-06-13
1798Access Control Violation - Sensitive Data Exposure Directory listing NA Nick Berrie (@machevalia) Bug Bounty2022-02-192023-06-13
1795XSS in hidden input field XSS NA Faizan Elahi Bug Bounty2022-02-212023-06-13
1794What an injection into jQuery-selector can lead to CSRF NA Anton Subbotin (@ska_vans) Bug Bounty2022-02-212023-06-13
1791OAuth and PostMessage - Chaining misconfigurations for your access token. OAuth postMessage Token leak NA Suraj Disoja (@ninetyn1ne_) Bug Bounty2022-02-212023-06-13
1789Write Up – Android Application Screen Lock Bypass Via ADB Brute Forcing Android Bruteforce Authentication bypass NA Omar Espino (@omespino) Bug Bounty2022-02-222023-06-13
1788CVE-2021-45467: CWP CentOS Web Panel – preauth RCE RCE LFI Arbitrary file write Centos Web Panel (CWP) Paulos Yibelo (@PaulosYibelo) Bug Bounty2022-01-222023-06-13
1786How I Hacked the Dutch Government with SQLi and Won the Famous T-Shirt? SQL injection Dutch Government Göktuğ Kaya (@g0ktugkaya) Bug Bounty2022-02-242023-06-13
1785Piercing the Cloud Armor - The 8KB bypass in Google Cloud Platform WAF WAF bypass Google Kloudle (@Kloudleinc) Bug Bounty2022-02-242023-06-13